SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60298 2026-07-21

CVE-2026-60298: Critical Unauthenticated Takeover in Oracle Coherence

"A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated, network-based attacker fully take over the product, addressed in Oracle's July 2026 Critical Patch Update."

A critical (CVSS 9.8) vulnerability in Oracle Coherence lets an unauthenticated, network-based attacker fully take over the product, addressed in Oracle's July 2026 Critical Patch Update.

What Is It

CVE-2026-60298 is a critical vulnerability in the Core component of Oracle Coherence, part of Oracle Fusion Middleware. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via TCP to compromise Oracle Coherence. Successful exploitation can result in complete takeover of Oracle Coherence. Oracle assigns it a CVSS 3.1 base score of 9.8 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network attack vector, low complexity, no privileges or user interaction required, and high impact to confidentiality, integrity, and availability.

Why It Matters

The combination of an unauthenticated network attack path, low attack complexity, and full compromise makes this among the most severe classes of vulnerability. No credentials or user interaction are needed, and a successful attack yields takeover of the affected Coherence instance. The impact score of 5.9 with a maximal exploitability score of 3.9 underscores how readily reachable exposed instances are. No CISA KEV entry was supplied, so active exploitation is not confirmed at this time; the severity alone warrants prompt remediation.

What's Vulnerable

The affected product is Oracle Coherence (vendor: Oracle Corporation), within Oracle Fusion Middleware, component Core. Supported versions listed as affected are:

Patch Status

Oracle addressed this vulnerability in its July 2026 Critical Patch Update (CPU). Administrators running the affected Coherence versions should apply the fixes documented in the Oracle July 2026 security alert. Given the unauthenticated, network-reachable nature of the flaw, patching should be prioritized. This CVE was published and last modified on 2026-07-21, with NVD status "Received."

Sources